All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89522: media: staging/ipu7: fix async notifier UAF on probe error path
@ 2026-09-11 19:43 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:43 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

media: staging/ipu7: fix async notifier UAF on probe error path

isys_register_devices() registers the V4L2 async notifier via
isys_notifier_init(). If a subsequent probe step such as
isys_fw_log_init() fails, isys_probe() jumps to the out_cleanup label
which only calls isys_unregister_devices(). That helper tears down the
video devices, subdevices, V4L2 device and media device, but never
unregisters or cleans up the async notifier.

As a result the notifier stays chained in the global notifier_list while
the enclosing struct ipu7_isys is freed by devres, leading to list
corruption and a use-after-free the next time the list is walked.

The remove path already does the right thing by calling
isys_notifier_cleanup() before isys_unregister_devices(). Mirror that on
the probe error path so the notifier is unregistered and cleaned up
before the device is torn down.

The Linux kernel CVE team has assigned CVE-2026-89522 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.17 with commit a516d36bdc3d8373f904af57c95e76d6f921cf1c and fixed in 6.18.50 with commit 2a8dd9fd12f3f6b21207cec8f50c92cd428e6b81
	Issue introduced in 6.17 with commit a516d36bdc3d8373f904af57c95e76d6f921cf1c and fixed in 7.2.4 with commit 323c411fb63122e8cef5b833032d69d59a838559
	Issue introduced in 6.17 with commit a516d36bdc3d8373f904af57c95e76d6f921cf1c and fixed in 7.3-rc1 with commit d7f48aa7d60c65d3e6d5312c27f17d5525a245fb

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89522
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/staging/media/ipu7/ipu7-isys.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/2a8dd9fd12f3f6b21207cec8f50c92cd428e6b81
	https://git.kernel.org/stable/c/323c411fb63122e8cef5b833032d69d59a838559
	https://git.kernel.org/stable/c/d7f48aa7d60c65d3e6d5312c27f17d5525a245fb

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 19:55 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:43 CVE-2026-89522: media: staging/ipu7: fix async notifier UAF on probe error path Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.